App: Hāngī Controller: Ahmed Naeem, Bernhardstraße 24, 04315 Leipzig, Germany, hello@gethangi.com Effective date: 13 September 2026 Version: 1.1
The data controller for personal data processed through the App is:
Ahmed Naeem Bernhardstraße 24, 04315 Leipzig, Germany Email: hello@gethangi.com
This Policy explains what personal data we process when you use the App, why, on what legal basis, who we share it with, how long we keep it, and your rights. It applies to guests and hosts alike.
a) Account data — email address, display name, and authentication data. If you sign in with Apple or Google, we receive basic profile identifiers from them per your choices.
b) Event & potluck content — events you create or join, including title, date/time, free-text location (e.g. an address you type), dishes/items, quantities, dietary tags, notes, and comments.
c) Participant & guest data — names and, where provided, email addresses or phone numbers of guests, RSVP status, and items claimed. Hosts may add this manually or import from device contacts (with your OS-level permission).
d) Invitations — invite codes/links you generate and their status.
e) Device & technical data — app version, device/OS type, language, and push-notification tokens (if you enable notifications). Our infrastructure providers also process technical logs and IP addresses to deliver and secure the Service.
f) Diagnostics — technical error logs generated by our infrastructure providers to keep the App stable and secure.
g) On-device only — "free potluck" drafts created without an account are stored locally on your device and are not sent to our servers until you sign in and choose to save them.
h) Shared costs (optional feature) — if you or others use the shared-cost ledger on an event, we process the expense description and amount, who paid, who it's split between, and repayment records (who paid whom, when, and whether it was confirmed). If you add a free-text note on your profile about how to pay you back (e.g. a payment-app handle or IBAN), we store that too. This is visible only to other participants of the same event who have a balance with you.
We do not process payments or move money — the App has no payment feature and the data in (h) is a user-entered record only, not payment data — we do not run advertising, and we do not sell personal data.
| Purpose | Data | Legal basis |
|---|---|---|
| Create/operate your account; provide core features | 3a–d | Performance of a contract — Art. 6(1)(b) |
| Deliver push notifications you enabled | 3a, 3e | Consent — Art. 6(1)(a) (device permission); withdraw any time in settings |
| Send transactional emails (e.g. sign-up code) | 3a | Performance of a contract — Art. 6(1)(b) |
| Keep the Service secure, prevent abuse, debug | 3e, 3f | Legitimate interests — Art. 6(1)(f) |
| Comply with legal obligations | as needed | Legal obligation — Art. 6(1)(c) |
Where you act as a host adding other people's contact details, you are responsible for having a lawful basis to share them with us; we process them to provide the Service to you.
We use trusted service providers who process data on our behalf under data-processing agreements:
| Provider | Role | Region |
|---|---|---|
| Supabase | Database, authentication, backend functions, and sending sign-up/login (OTP) emails (hosting of most data) | EU |
| Expo (EAS) | App builds, over-the-air updates, push-notification routing | USA |
| Apple (APNs) | iOS push delivery | USA |
| Google Firebase Cloud Messaging | Android push delivery | USA |
| Vercel | Hosting of invite/app-link web pages | Global CDN (incl. USA) |
| Apple / Google | Sign-in (if you use social login); app-store distribution | USA |
We share personal data only as needed to run the Service, to comply with law, or to protect rights and safety. We do not sell it.
Some providers are located outside the EU/EEA (e.g. the USA). Where we transfer personal data internationally, we rely on appropriate safeguards under GDPR Chapter V, primarily the EU Standard Contractual Clauses and, where applicable, the provider's participation in the EU–US Data Privacy Framework, plus supplementary measures. You can request more information at hello@gethangi.com.
Our database, authentication and account data are hosted in the EU (Supabase EU region). Transfers arise mainly for push delivery, app distribution and web-page hosting.
We keep personal data only as long as needed for the purposes above: - Account data: for the life of your account. - Event/participant content: until you or the host delete it, or the account is deleted. - Push tokens: until you disable notifications or uninstall. - Diagnostics/logs: for a limited period (up to 90 days) then deleted or anonymised. - Backups: may persist for a limited additional period before rotation.
When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must retain it to comply with a legal obligation or to establish/exercise/defend legal claims.
You have the right to: access your data; rectify inaccurate data; erase ("right to be forgotten"); restrict processing; data portability; and object to processing based on legitimate interests. Where processing is based on consent, you may withdraw it at any time without affecting prior processing.
To exercise these rights, contact hello@gethangi.com. You can also delete your account (and its data) directly in the App via Profile → Delete account. We will respond within the statutory time (generally one month).
You also have the right to lodge a complaint with a supervisory authority — for example your local Data Protection Authority. In Germany this is the authority of your federal state (Landesdatenschutzbehörde).
The App is not intended for children under 16. We do not knowingly collect their personal data. If you believe we have, contact hello@gethangi.com and we will delete it.
We use technical and organisational measures appropriate to the risk — including encryption in transit (HTTPS/TLS), access controls, Row-Level Security in the database, and secure credential storage on-device. No method of transmission or storage is 100% secure, but we work to protect your data and to notify you and authorities of breaches where legally required.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
We may update this Policy. Material changes will be notified in-app or by email before they take effect. The "Effective date" above shows the current version.
Questions or requests: hello@gethangi.com — Ahmed Naeem, Bernhardstraße 24, 04315 Leipzig, Germany.